Worked case · Reference condition · 12 figures

Event-driven profile refresh

Refresh through events and risk

Figure 01 / 12

The population that monitoring actually sees

The population that monitoring actually sees — Event-driven profile refresh. Count; profile-change signals in one day. Exact values are in the figure data below.
Count; profile-change signals in one day

9,114 of 9,300 source items enter this monitoring calculation. The missing 186 items are a coverage gap, not evidence of low risk. Reconcile stable identifiers and amounts where appropriate before interpreting the alert rate.

Figure data and text version
Population stateItems
Included in monitoring9,114
Absent from this run186

A material change in activity or reliable ownership evidence can make an earlier profile stale. A periodic schedule alone may miss the relevant event.

The reference case starts with the stated population and a functioning evidence path. The owner is risk operations.

All amounts, rates, capacity limits, and outcomes in this case are synthetic. The three conditions are separate assumptions for comparison. A better result in the response condition is not measured proof that the proposed control causes that improvement. The figures expose the calculation and its limits; a real deployment needs its own evidence.

Read the result

The daily source population is 9,300 items, but 186 are outside the completed monitoring run. The included population creates 292 hits and 239 unique cases. With 42 cases already open and capacity for 250, the queue closes at 31. Coverage, duplicate work, and staffing are separate causes; reducing one number does not prove that the overall control improved.

Model inputs and calculated values

Inputs below are the case-specific values. Each figure states the condition-specific assumptions and units used in its calculation. Calculated values are rounded for display.

InputValue
population9,300
alertRate0.032
capacity250
backlog42
Calculated valueResult
population9,300
covered9,114
missing186
raw292
duplicates53
cases239
opening42
resolved250
closing31
capacity250
Figure 02 / 12

From scenario hits to unique cases

From scenario hits to unique cases — Event-driven profile refresh. Count; hit and case units differ. Exact values are in the figure data below.
Count; hit and case units differ

292 raw hits become 239 cases after removing 53 repeated references to the same case under the stated merge rule. Deduplication should reduce duplicate work while retaining the underlying events and reasons. It must not merge unrelated activity merely because values look similar.

Figure data and text version
StageCount
Raw scenario hits292
Duplicate references53
Unique cases239
Figure 03 / 12

The queue balance is an accounting identity

The queue balance is an accounting identity — Event-driven profile refresh. Cases per day. Exact values are in the figure data below.
Cases per day

Opening backlog 42 + arrivals 239 − completed cases 250 = closing backlog 31. Completion is capped by both available work and the stated capacity. This identity is useful even when average handling times are uncertain.

Figure data and text version
MovementCasesDefinition
Opening backlog42Unresolved at window start
New cases239Unique arrivals in this window
Completed250Reached a defined completion state
Closing backlog31Unresolved at window end
Figure 04 / 12

Backlog accumulates across uneven days

Backlog accumulates across uneven days — Event-driven profile refresh. Cases unresolved at day end. Exact values are in the figure data below.
Cases unresolved at day end

This deterministic six-day example applies a stated daily arrival multiplier and a constant completion capacity. Unused capacity does not carry forward as completed work. The series is a workload illustration; it omits variable case durations and specialist routing. Horizontal positions are the labeled observations or scenarios; equal spacing does not imply equal numerical increments.

Figure data and text version
DayClosing backlog
D131
D20
D337
D4145
D5158
D675
Figure 05 / 12

Arrivals and completions need separate plots

Arrivals and completions need separate plots — Event-driven profile refresh. Cases per day. Exact values are in the figure data below.
Cases per day

The service line cannot exceed the work available that day. A team can complete more cases than arrive while clearing an opening backlog. Conversely, stable staffing can coexist with a growing queue when arrivals remain higher than capacity. Horizontal positions are the labeled observations or scenarios; equal spacing does not imply equal numerical increments.

Figure data and text version
DayArrivalsCompletions
D1239250
D2203234
D3287250
D4358250
D5263250
D6167250
Figure 06 / 12

An illustrative age profile of open work

An illustrative age profile of open work — Event-driven profile refresh. Cases; constructed snapshot. Exact values are in the figure data below.
Cases; constructed snapshot

The closing backlog is 31 cases. The 50/30/remainder split is an explicit illustrative age allocation, not a distribution inferred from the arrival model. Production age buckets must come from each case’s actual receipt and status history.

Figure data and text version
Age bucketOpen cases
Under one day16
One to three days9
Over three days6
Figure 07 / 12

Completion outcomes are not criminal labels

Completion outcomes are not criminal labels — Event-driven profile refresh. Completed review tasks; synthetic disposition allocation. Exact values are in the figure data below.
Completed review tasks; synthetic disposition allocation

Of 250 completed review tasks, 42 are referred for further assessment, 30 need another evidence action, and 178 close under the stated procedure. These are operational outcomes. None is a probability of money laundering or a substitute for a reporting decision.

Figure data and text version
Review dispositionTasks
Referred for assessment42
Further evidence action30
Closed under procedure178
Figure 08 / 12

Known-event tests assess specific coverage

Known-event tests assess specific coverage — Event-driven profile refresh. Synthetic coverage test. Exact values are in the figure data below.
Synthetic coverage test

The injected test set contains 100 known test events designed to exercise refresh through events and risk. The system surfaces 92. That 92% detection result measures this constructed test set only; it does not establish population-wide detection of illicit activity.

Figure data and text version
MeasureCountInterpretation
Injected known events100Defined test population
Detected by the scenario92Expected evidence reached the control
Not detected8Investigate data, logic, and delivery
Real-world illicit prevalenceUnknownNot inferred from this test
Figure 09 / 12

Data quality has several independent dimensions

Data quality has several independent dimensions — Event-driven profile refresh. Count; overlapping field checks. Exact values are in the figure data below.
Count; overlapping field checks

Each row is a different field requirement over the same source population. Completeness alone does not establish that values are accurate or current. The case uses explicit illustrative missing counts to show how data quality can affect scenario coverage.

Figure data and text version
Field requirementPresentAbsent
Party reference9,25446
Event time9,20793
Counterparty context9,021279
Figure 10 / 12

Type the relationship before drawing an inference

Type the relationship before drawing an inference — Event-driven profile refresh. Typed evidence relationships. Exact values are in the figure data below.
Typed evidence relationships

This evidence map distinguishes a customer relationship, a transfer, and a case reference. The links support refresh through events and risk; they do not imply common ownership or intent. A shared data point is a lead whose meaning depends on source, time, and context.

Figure data and text version
FromToRelationship
Event-driven profile refreshCounterparty AObserved transfer
Event-driven profile refreshProfile recordDeclared business
Counterparty ACase recordEvidence reference
Profile recordCase recordContext for review
Figure 11 / 12

Case clocks start from defined events

Case clocks start from defined events — Event-driven profile refresh. Illustrative internal timing. Exact values are in the figure data below.
Illustrative internal timing

A legal deadline, an internal response target, and an evidence-expiry date can start from different events. The hours here are internal teaching targets only. They are not BSA, sanctions, consumer-protection, or other statutory deadlines.

Figure data and text version
EventRelative timeOperational meaning
Source eventT0Activity occurred
Data arrivalT0 + 2 hoursThe monitoring system learned it
Case createdT0 + 3 hoursWork entered an owned queue
Internal review targetT0 + 27 hoursIllustrative 24-hour target from case creation
DispositionRecorded separatelyUse actual decision and reporting records
Figure 12 / 12

The end-to-end delivery contract

The end-to-end delivery contract — Event-driven profile refresh. Operational control path. Exact values are in the figure data below.
Operational control path

The scenario is incomplete until the intended evidence reaches an owned case. For refresh through events and risk, verify source coverage, hit creation, queue acceptance, reviewer access, and final disposition separately. A green job status proves only that a job reported completion.

Figure data and text version
BoundaryAcceptance evidence
Source to scenario9114 included source items; 186 missing
Scenario to case292 hits linked to 239 unique cases
Case to reviewerRequired evidence visible under the reviewer role
Reviewer to outcomeDisposition, rationale, and any separate reporting decision retained

Connect the result to the system

Use defined event triggers and preserve the history of profile changes and supporting facts.

Check the population, evidence, permitted action, and actual effect together. A balanced calculation can still use the wrong population; a successful response can still leave an unknown financial outcome. The case’s numerical result applies only to its stated assumptions.

Sources and further reading

The chapter sources support the concepts and scope. They do not prescribe the synthetic model rates.

  1. FinCEN: Customer Due Diligence Rule and current resources
  2. FinCEN: FIN-2026-R001 beneficial-owner exceptive relief
  3. FFIEC: Customer Due Diligence (historical examination material; read with current FinCEN rules)